Sub-groups resolution is rejected and Member Type is set to "Account" instead of "Group" for Account Collectors in RSA Identity Governance and Lifecycle
Originally Published: 2017-10-03
Last Modified: 2023-11-30
Article Number
Applies To
RSA Version/Condition: 6.9.1 P15- P19, 7.0.0 P04, 7.0.1
Issue
In the following example, we are using groups and sub-groups collected from Active Directory.
1. We have two groups in AD as below
2.Sub-Group is the member of Top-Group.
3. Account Collector with the below configuration for the groups.
4. Following is the subgroup resolution.
5. Collect data, then check the monitoring >> raw data >> Group Membership tab, you will find that the Top-Group to Sub-Group resolution is failing and the Sub-Group is collected as an "Account", not as a "group":
Cause
For version 7.0.0 and 7.0.1 this is fixed in 7.0.0 P05 and 7.0.1 P02 respectively.
Resolution
Related Articles
Sub menu buttons defined in drop-down request buttons may have truncated text in RSA Identity Governance & Lifecycle 19Number of Views The review "Include sub-groups" option does not include sub-groups in the review in RSA Identity Governance and Lifecycle 32Number of Views How many levels of Sub-CA chaining are supported in Sentry CA 3.x? 9Number of Views Role and Group Review Result behavior when members/entitlements are added to the underlying review items in RSA Identity G… 40Number of Views Error message "Access denied - User not a member of any identity source in access policy" in RSA SecurID Access 81Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?